Student records
The offices that own the official student record. Applications and transcripts arrive from Slate, Common App, and the SIS; award files run through verification and appeals; transcripts release inside the 45-day FERPA window.
StudentDocs runs admissions, financial aid, the registrar, sponsored research, and the seven other offices that own records, on the same architecture that holds federal records under FedRAMP and DISA-JITC. Every access writes to one append-only audit log.
FERPA · GLBA · HIPAA · NIST 800-171 · state public records · Title IX, with every access on one append-only audit log. FedRAMP Moderate authorized · DoDM 8180.01 aligned (JITC-tested under the legacy 5015.02-STD) · built and owned in Fort Washington, PA.
FERPA governs the student record. GLBA governs the aid file. NIST 800-171 covers anything CUI that arrives with a federal grant. State law and Title IX layer their own rules on top. And the records don't sit in one system.
They live in Banner, PeopleSoft, Workday, M365, Google Workspace, file shares, and the paper folders some offices still keep, and the records officer is responsible for all of it. StudentDocs takes responsibility for the records once they exist, wherever they live. Capture normalizes the metadata, the vault holds the authoritative copy, the audit log records every access, and retention runs against each office's schedule.

Eleven departmental workflows, organized into five family modules, each on the same vault, identity layer, and audit log, each shipping with the document types, workflows, and retention rules the family actually uses.
The offices that own the official student record. Applications and transcripts arrive from Slate, Common App, and the SIS; award files run through verification and appeals; transcripts release inside the 45-day FERPA window.
Federally-funded research carries federal records obligations. Grant files, IRB and IACUC records, and CUI from research contracts sit in the same vault, under the same audit log, as the registrar's transcripts.
Personnel files, tenure dossiers, search-committee records, and faculty contracts, plus gift records, donor files, and planned-giving documentation, separated from FERPA-protected records at the access layer where policy requires it.
Open-records requests, subpoena response, litigation hold, and e-discovery, alongside Title IX files with separated roles, an evidence chain, and litigation hold. Both run on the same exemption logic and redaction tooling as Feith's federal FOIA Workbench.
Counseling, health-services, vaccination, and accommodation records, held under the FERPA medical-record exception or under HIPAA where the campus health center is a covered entity, with ADA accommodation records kept separate.
StudentDocs treats FERPA as a structural requirement. Every access to a student record writes to an append-only log, the 45-day access window is a tracked workflow, and the school-official exception is logged with the determination that justified it.
The clock starts on the request. The package returned to the requester is itself recorded.
Federally-funded research carries federal records obligations: CUI markings, NIST 800-171 controls, ITAR and EAR export controls, CMMC posture for DoD work. StudentDocs handles them on the same platform that handles your registrar's transcripts. The research office stops standing up parallel systems to satisfy compliance.
State public-records requests arrive with a clock attached. Title IX files have to be retained, redacted, disclosed selectively, and held for years. Both run on the same vault, with the same exemption logic and redaction tooling as Feith's federal FOIA Workbench.
Open-records and sunshine laws apply to public universities and, in specific contexts, to private institutions. StudentDocs runs each request as a tracked case: intake, scoping, search, redaction, exemption application, release package, response letter.
The Title IX framework has shifted repeatedly since 2020. StudentDocs doesn't pin to any one version of the rule: it holds investigation files with need-to-know access, separates investigator and decision-maker roles, keeps an evidence chain, and applies litigation hold the moment a notice is logged.
StudentDocs runs on the identity layer your campus already uses, and runs lifecycle and audit across records wherever they live, without forcing a migration.
CAS, Shibboleth, SAML, OIDC, AD / LDAP, and MFA: the login your campus already uses, with role attributes derived from the SIS. Need-to-know access is enforced per record, per field, per workflow step.
Append-only, hash-chained, anti-tamper, with Splunk / SIEM forwarding. The audit architecture that holds federal records under DISA-JITC certification holds your campus access log too.
Records in M365 stay in M365; records in Google stay in Google; file shares stay file shares. StudentDocs runs retention, holds, disposition, and audit against them in place: the vault is the source of truth, the storage stays where users work.
Most campuses come from OnBase, Banner Document Management, Laserfiche, Perceptive Content, or a homegrown stack. The migration runs in three phases, one at a time, so the path stops being all-or-nothing.
Records flow into StudentDocs from your existing systems while your incumbent ECM keeps running. Identity and audit consolidate first; the new vault carries everything that arrives after go-live without touching the legacy archive.
8 to 16 weeks to deploy. No system retires in this phase.
Pick the office with the most pain. Sponsored Programs and Financial Aid are common first choices. Move that office's workflow, then repeat on a schedule the campus controls. Each cutover is independent.
4 to 8 weeks per department, sequenced to your priorities.
Some campuses retire the incumbent ECM once active workflows have moved; others keep it as a read-only archive. Either way, the StudentDocs vault holds the authoritative copy of anything still in flight.
When the campus is ready. The decision is reversible.
A state university CIO doesn't have to argue the architecture from first principles. The vault, audit log, identity layer, and lifecycle services under StudentDocs are the same components the National Archives and the Department of Defense evaluated, against their own standards, before authorizing them.
A 45-minute walkthrough with a StudentDocs lead, usually with the records officer and one other stakeholder. We work through your actual records workflow and show you what StudentDocs does in the office with the most pain.
Thanks. A StudentDocs lead will reach out within one business day to schedule your walkthrough.